logo

SmartRAT ClickFix Campaign Identified

ID: 95d0c99b-f3ae-514a-a52c-7df534b6311e

STIX ID: report--95d0c99b-f3ae-514a-a52c-7df534b6311e

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-24

Date Updated: 2026-06-24

Author: Do Son

...
...

**Executive summary:** Threat actors are using AI-generated typosquatting websites and fake system/browser error screens to coerce Brazilian banking customers into pasting a malicious PowerShell command that installs SmartRAT (Banana RAT); the malware runs in-memory, escalates privileges, establishes persistent System-level services, communicates with encrypted TCP C2, and can capture credentials, screen streams, keylogs, and QR codes to facilitate financial fraud — defenders should block squatted domains, monitor unusual PowerShell activity and scheduled tasks, and enforce application control.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.